CVE-2019-25459

Szczegóły podatności CVE.
Aktualizacja: 04.03.2026, 01:54 (CET)
non-KEV CVSS 9.8 EPSS 0.0011 Score 29.47

Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into parameters like emlak_durumu, emlak_tipi, il, ilce, kelime, and semt to extract sensitive database information or perform time-based blind SQL injection attacks.

Źródła

ŹródłoLinkUwagi
NVD (NIST)https://nvd.nist.gov/vuln/detail/CVE-2019-25459Karta CVE w NVD
CISA KEVhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-25459Wyszukiwanie CVE w KEV
FIRST EPSShttps://api.first.org/data/v1/epss?cve=CVE-2019-25459API EPSS dla CVE
disclosure@vulncheck.comhttps://www.exploit-db.com/exploits/47142Exploit
disclosure@vulncheck.comhttps://www.vulncheck.com/advisories/web-ofisi-emlak-sql-injection-via-emlak-arahtmlBroken Link
disclosure@vulncheck.comhttps://www.web-ofisi.com/detay/emlak-scripti-v3.htmlProduct